Known vulnerabilities in ruby2.3 (Debian package) 2.3.3-1+deb9u3
Vendor:
Debian
Software:
ruby2.3 (Debian package)
Version:
2.3.3-1+deb9u3
Software CPE:
cpe:2.3:o:debian:ruby2_3_debian_package:*:*:*:*:*:debian_linux:*:*
Website:
https://www.debian.org/
Total vulnerabilities:
4
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.2
Vulnerabilities by Severity
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU23009 - Improper Control of Generation of Code ('Code Injection') CVE-2019-16255 |
CWE-94 | High | 2.3.3-1+deb9u7 | 27.11.2019 |
SB2019100211 SB2019112701 SB2019121714 and 14 more |
||
| #VU23008 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2019-16254 |
CWE-113 | Medium | 2.3.3-1+deb9u7 | 27.11.2019 |
SB2019100211 SB2019112701 SB2019121714 and 14 more |
||
| #VU23007 - Improper input validation CVE-2019-16201 |
CWE-20 | Medium | 2.3.3-1+deb9u7 | 27.11.2019 |
SB2019100211 SB2019112701 SB2019121714 and 14 more |
||
| #VU23006 - Improper input validation CVE-2019-15845 |
CWE-20 | Medium | 2.3.3-1+deb9u7 | 26.11.2019 |
SB2019100211 SB2019112701 SB2019121714 and 15 more |